{"id":"CVE-2018-17186","aliases":["GHSA-qfjv-998w-q48f"],"url":"https://o3.security/vulnerability/CVE-2018-17186","summary":"Improper Restriction of XML External Entity Reference in org.apache.syncope:syncope-core","details":"An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.","published":"2018-11-06T20:29:00.217Z","modified":"2026-07-08T19:44:26.146431Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.02386,"percentile":0.82522,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.syncope:syncope-core","fixedVersion":"2.0.11"},{"ecosystem":"Maven","name":"org.apache.syncope:syncope-core","fixedVersion":"2.1.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:44:26.146431Z"}}